In mid-2022, an employee at an Iowa company did something finance teams do every day: paid vendor invoices.

The vendors were familiar. The requests appeared legitimate. The company intended to pay what it owed.

There was just one problem. The payment instructions belonged to a fraudster.

More than $800,000 went to the wrong account.

Then came the recovery effort. Investigators followed the money through multiple accounts and seized $372,583.77 from one Wells Fargo account. On September 24, 2026, roughly four years after the payment, a federal court entered a judgment forfeiting those funds.

That judgment is a win. Investigators found a substantial amount of money, preserved it, and proved its connection to the scheme.

It is also a useful reality check.

The payment took minutes. The legal process surrounding part of the proceeds took years.

What the Iowa BEC Case Actually Tells Us

According to the U.S. Attorney’s Office for the Northern District of Iowa, the fraudster impersonated vendors working with the company and directed an employee to send invoice payments to a fraudulent account.

Nothing about that scenario is exotic. There was no dramatic breach of a bank vault. The employee was real. The vendors were real. The invoices may have looked completely ordinary. The company genuinely meant to pay them.

The attacker only needed to change one detail: where the money went.

That is what makes business email compromise so effective. It does not always defeat the payment system. Often, it simply feeds the payment system a convincing lie.

The bank can execute the instruction perfectly and the money can still land in the wrong place.

The Iowa case also needs one important caveat. The Justice Department’s announcement refers to other seizures, but it does not disclose the total amount recovered, whether the victim has received restitution, or when any recovered funds will reach the victim. So it would be misleading to say the company recovered less than half of its loss.

What we can say is more important anyway: even a successful recovery can be slow, complicated, and uncertain.

Recovery Is a Backstop, Not a Strategy

When a fraud loss becomes public, the first question is usually: How much did they get back?

It is an understandable question. It is also too narrow.

By the time stolen funds are frozen, the victim may have spent weeks working with banks, law enforcement, lawyers, insurers, and internal teams. Projects may be delayed. Vendor relationships may be strained. Leadership may be trying to understand how an approved payment reached the wrong account.

And the real vendor may still need to be paid.

That last point is easy to miss. A fraudster can steal the payment, but cannot erase the underlying obligation. The victim may face the loss and the original invoice at the same time.

Even when money is located, getting it back is not the same as reversing a card charge. Funds may have moved through several accounts. Different parties may claim an interest in them. Investigators must trace the path, and courts may need to decide what happens next.

The system can work exactly as intended and still leave the victim waiting.

BEC Hijacks the Decision Before the Payment

The FBI recorded 24,768 business email compromise complaints and more than $3 billion in reported losses in 2025. It has also reported more than $55 billion in exposed losses from October 2013 through December 2023.

Those numbers are enormous, but the mechanics are often painfully mundane. An urgent message arrives. A familiar name appears in the sender field. Payment instructions have “changed.” Someone is waiting. The transaction needs to close.

Under pressure, a plausible request can feel like a routine request.

That is why “we checked the email” is not enough. Neither is a callback made using the phone number in the same message, or a verbal confirmation that leaves no reliable record.

Before a high-value payment goes out, the organization should be able to answer a few basic questions with evidence:

  • Who provided the instructions?
  • Which organization does that person represent?
  • Are they authorized to act for this transaction?
  • Does the receiving account belong to the intended recipient?
  • Who approved that account for this specific payment?
  • Can we prove each of those steps later?

If the bank account changes, the scrutiny should change too. A request to redirect funds is not a routine edit. It is a new risk event.

Secure the Transaction, Not Just the Payment

Most payment controls focus on the final step: Was the transfer approved? Was the routing number entered correctly? Did the bank authenticate the user?

Those checks matter. But they begin too late if the person, authority, or destination account has already been misrepresented.

The better approach is to secure the transaction that produces the payment.

That means verifying the participants, connecting each person to the organization they represent, confirming their authority, validating the receiving account, capturing the right approvals, and preserving the evidence in one place.

It also means planning for residual risk. No security control can promise that fraud will never happen. Transaction-specific insurance can provide defined protection for eligible payments when something still goes wrong.

Prevention and protection solve different problems:

  • Prevention asks whether the money should move in the first place.
  • Evidence shows which controls were completed and by whom.
  • Protection establishes who bears a covered loss if those controls are not enough.
  • Recovery starts after the money is already gone.

All four matter. But they are not interchangeable.

The Question to Ask Before the Next Payment

The Iowa judgment is encouraging. It shows that—in some cases—investigators can trace stolen funds and courts can preserve fraud proceeds for lawful disposition.

But no finance leader wants a four-year recovery story.

They want the payment to reach the right account the first time.

Basefund helps institutions do that by bringing identity verification, bank account validation, roles and permissions, documented approvals, and insurance for eligible payments into one secure transaction workflow.

For municipal issuers, corporate trust teams, advisors, and other organizations moving high-value funds, the goal is not to add another box to check. It is to replace scattered emails, informal callbacks, and disconnected approvals with a transaction record everyone can trust.

Because once the money moves, the question becomes, “Can we get it back?”

Before it moves, there is a much better question: “Have we proved where it should go?”

See how Basefund can help secure your payment workflow.

Sources